First published: Wed Dec 16 2015(Updated: )
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/k8s.io/kubernetes | <1.2.0-alpha.6 | 1.2.0-alpha.6 |
Kubernetes Dashboard | ||
Red Hat OpenShift | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7561 is considered a medium severity vulnerability due to the potential exposure of private images.
To fix CVE-2015-7561, upgrade Kubernetes to version 1.2.0-alpha.6 or later and ensure proper image access controls are in place.
CVE-2015-7561 affects users of Kubernetes in OpenShift 3 who might have access to private images without proper authorization.
Users who are aware of the names of private images can potentially use them even if they do not have permission to access these images.
CVE-2015-7561 specifically affects Kubernetes version 1.2.0-alpha.6 and earlier in the context of OpenShift 3.